[Sw_assurance] Help With Software Assurance Scope
heyes at jlab.org
heyes at jlab.org
Thu Jul 30 17:38:08 EDT 2009
Matt,
good point about the critical FPGA code on the random PC in someone's
trailer. I was thinking more about my group and Chris' group that
already have good practices and QA. I agree that we should document
that. What I am trying to avoid is another "good practice" layer
being put on top existing practices that are sufficient or more than
sufficient.
If we are going to discuss FPGAs we should include Chris Cuevas.
Graham
> Kelly Mahoney wrote:
> <snipped>
>> This procedure only applies to security software configuration items
>> insofar as the impact ineffective security software controls may
>> materially affect operations and safety.
>
> Kelly,
> Did you mean the paragraph above to refer to cybersecurity in
> particular, or do you really want to include all security
> software in the scope?
>
> Graham Heyes wrote:
>> As far as FPGAs are concerned they should be exempt in everything except
>> safety interlocks and systems controlling hardware that would cause
>> damage or injury if the FPGA misbehaved.
>
> I don't agree with Graham. A QA process doesn't just try
> to protect us from misbehaving software, it also ensures
> that we can maintain and support our software products. If we
> have an FPGA critical to data acquisition and programmed with code
> that lives on some person's PC (and not backed up), and that person
> leaves the lab, what does the lab do if it needs to be modified?
> Who knows where the code is, or what it does? A good QA process will
> ensure we have the documentation and data to continue to provide
> support. Without the QA process the lab would have to start over.
>
> --
> Matthew Bickley Email: bickley at jlab.org
> Computer Scientist Telephone: 757-269-7347
> TJNAF
> _______________________________________________
> Sw_assurance mailing list
> Sw_assurance at jlab.org
> https://mailman.jlab.org/mailman/listinfo/sw_assurance
>
More information about the Sw_assurance
mailing list